[ xman25 @ 11.11.2009. 17:18 ] @
Nedavno mi je pocela da iskace ova poruka pri pokretanju Mozille ali kada sam isao na OK Mozilla se normalno otvori. Od danas nakon pojavljivanja ove poruke Mozilla nece da se otvori vec izbaci ovu poruku: ![]() Probao sam sa brisanjem Mozille i ponovnom instalacijom i nista i sa system restore na prethodni dan ali takodje ostaje nepromenjeno. Znaci sada ne mogu vise uopste da pokrenem Mozillu, uvek mi izbacuje one dve poruke. Uradio sam log preko ComboFix-a: Citat: ComboFix 09-11-11.01 - Administrator 11.11.2009 17:48.1.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1250.381.1033.18.2047.1411 [GMT 1:00] Running from: c:\users\Administrator\Desktop\ComboFix.exe AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} FW: Outpost Firewall Pro *disabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD} WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\program files\Dealio Toolbar c:\program files\Dealio Toolbar\config.ini c:\program files\Dealio Toolbar\DealioToolbarIE.dll c:\program files\Dealio Toolbar\Res\amazon.gif c:\program files\Dealio Toolbar\Res\apple.gif c:\program files\Dealio Toolbar\Res\barnes.gif c:\program files\Dealio Toolbar\Res\bestbuy.gif c:\program files\Dealio Toolbar\Res\dealio_logo.gif c:\program files\Dealio Toolbar\Res\dealio_logo_hover.gif c:\program files\Dealio Toolbar\Res\ebay.gif c:\program files\Dealio Toolbar\Res\icon_settings.gif c:\program files\Dealio Toolbar\Res\macys.gif c:\program files\Dealio Toolbar\Res\newegg.gif c:\program files\Dealio Toolbar\Res\overstock.gif c:\program files\Dealio Toolbar\Res\search-button-hover.gif c:\program files\Dealio Toolbar\Res\search-button.gif c:\program files\Dealio Toolbar\Res\search-chevron-hover.gif c:\program files\Dealio Toolbar\Res\search-chevron.gif c:\program files\Dealio Toolbar\Res\search_amazon.gif c:\program files\Dealio Toolbar\Res\search_dealio.gif c:\program files\Dealio Toolbar\Res\search_ebay.gif c:\program files\Dealio Toolbar\Res\search_yahoo.gif c:\program files\Dealio Toolbar\Res\separator.gif c:\program files\Dealio Toolbar\Res\target.gif c:\program files\Dealio Toolbar\Res\walmart.gif c:\program files\Dealio Toolbar\Res\widgets.xml c:\program files\Dealio Toolbar\SeARchsettings.dll c:\program files\Dealio Toolbar\SearchSettings.exe c:\program files\Dealio Toolbar\SearchSettingsRes409.dll c:\program files\Dealio Toolbar\sscfg.ini c:\program files\Dealio Toolbar\WidgiHelper.exe c:\program files\Fast Browser Search c:\program files\Fast Browser Search\1.bat c:\program files\Fast Browser Search\about.html c:\program files\Fast Browser Search\affid.dat c:\program files\Fast Browser Search\basis.xml c:\program files\Fast Browser Search\basis_br.xml c:\program files\Fast Browser Search\basis_de.xml c:\program files\Fast Browser Search\basis_en.xml c:\program files\Fast Browser Search\basis_es.xml c:\program files\Fast Browser Search\basis_fr.xml c:\program files\Fast Browser Search\basis_it.xml c:\program files\Fast Browser Search\basis_nr.xml c:\program files\Fast Browser Search\basis_pt.xml c:\program files\Fast Browser Search\basis_ru.xml c:\program files\Fast Browser Search\basis_tr.xml c:\program files\Fast Browser Search\BHO.dll c:\program files\Fast Browser Search\ClearRecycleBin.exe c:\program files\Fast Browser Search\error.html c:\program files\Fast Browser Search\FBSPlugin.dll c:\program files\Fast Browser Search\fbsProtection.xml c:\program files\Fast Browser Search\FbsSearchProvider.xml c:\program files\Fast Browser Search\FbsSearchProviderIE8.exe c:\program files\Fast Browser Search\FBStoolbar.dll c:\program files\Fast Browser Search\fbstoolbar.jar c:\program files\Fast Browser Search\fbstoolbar.manifest c:\program files\Fast Browser Search\icons.bmp c:\program files\Fast Browser Search\IE\basis.xml c:\program files\Fast Browser Search\IE\fbsSearchProvider.xml c:\program files\Fast Browser Search\IE\FBStoolbar.exe c:\program files\Fast Browser Search\IE\search_de.bmp c:\program files\Fast Browser Search\IE\search_es.bmp c:\program files\Fast Browser Search\IE\search_fr.bmp c:\program files\Fast Browser Search\IE\search_it.bmp c:\program files\Fast Browser Search\IE\search_pt.bmp c:\program files\Fast Browser Search\IE\search_ru.bmp c:\program files\Fast Browser Search\IE\SearchGuardPlus.exe c:\program files\Fast Browser Search\IE\SearchGuardPlus.ico c:\program files\Fast Browser Search\IE\SGPU.ico c:\program files\Fast Browser Search\info.txt c:\program files\Fast Browser Search\local.xml c:\program files\Fast Browser Search\logobg.bmp c:\program files\Fast Browser Search\MTWBtoolbar.html c:\program files\Fast Browser Search\search.bmp c:\program files\Fast Browser Search\search_br.bmp c:\program files\Fast Browser Search\SGPUpdaterS.exe c:\program files\Fast Browser Search\tbhelper.dll c:\program files\Fast Browser Search\tbs_include_script_003175.js c:\program files\Fast Browser Search\tbs_include_script_005064.js c:\program files\Fast Browser Search\tbs_include_script_012817.js c:\program files\Fast Browser Search\Toolbar Help.htm c:\program files\Fast Browser Search\uninstall.exe c:\program files\Fast Browser Search\uninstalSGP.exe c:\program files\Fast Browser Search\uninstalSGPU.exe c:\program files\Fast Browser Search\update.exe c:\program files\Fast Browser Search\version.txt c:\program files\SGPSA c:\users\Administrator\My Documents\cc_20091103_005612.reg c:\windows\system32\d3d10core.dll c:\windows\system32\kernel32new.dll c:\windows\system32\msvcrtnew.dll c:\windows\version.txt c:\windows\system32\LogonUI.exe . . . is infected!! . ((((((((((((((((((((((((( Files Created from 2009-10-11 to 2009-11-11 ))))))))))))))))))))))))))))))) . 2009-11-11 15:37 . 2009-11-11 15:37 -------- d-----w- c:\windows\system32\wbem\Repository 2009-11-10 19:45 . 2009-11-10 19:45 -------- d-----w- c:\program files\eGames 2009-11-08 18:04 . 2009-11-08 18:04 10880192 ----a-w- c:\users\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe 2009-11-07 23:42 . 2009-11-07 23:42 -------- d-----w- c:\program files\BS player 2009-11-07 23:00 . 2009-11-07 23:02 -------- d-----w- c:\program files\Your Uninstaller 2009-11-07 22:54 . 2009-11-07 22:58 -------- d-----w- c:\program files\Your Uninstaller 2008 2009-11-07 20:31 . 2009-11-07 20:33 6147544 ----a-w- c:\users\Administrator\Application Data\GRETECH\GomPlayer\GrLauncherTempSetup.exe 2009-11-07 20:31 . 2007-03-22 10:46 126976 ----a-w- c:\users\Administrator\Application Data\GRETECH\GomPlayer\GrLauncher.exe 2009-11-05 00:04 . 2009-11-05 00:04 152576 ----a-w- c:\users\Administrator\Application Data\Sun\Java\jre1.6.0_17\lzma.dll 2009-11-04 16:00 . 2009-11-04 18:26 -------- d-----w- c:\users\All Users\Application Data\FarmFrenzy3 2009-11-04 15:59 . 2009-11-04 15:59 -------- d-----w- c:\program files\LeeGTs Games 2009-11-03 16:51 . 2009-11-03 16:51 93360 ----a-w- c:\windows\system32\drivers\SBREDrv.sys 2009-11-03 16:51 . 2009-11-03 16:51 93360 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\SBREDrv.sys 2009-11-03 16:51 . 2009-11-03 16:51 554280 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\sbap.dll 2009-11-03 16:51 . 2009-11-03 16:51 212480 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\VipreBridge.dll 2009-11-03 16:51 . 2009-11-03 16:51 283944 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\Vipre.dll 2009-11-03 16:51 . 2009-11-03 16:51 1223976 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBTE.dll 2009-11-03 16:51 . 2009-11-03 16:51 242984 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBRE.dll 2009-10-29 02:03 . 2009-10-29 02:03 -------- d-----w- c:\users\Default User\Local Settings\Application Data\Microsoft Help 2009-10-26 14:52 . 2009-10-26 14:52 -------- d-----w- c:\users\All Users\Application Data\2BrightSparks 2009-10-26 14:52 . 2009-10-26 14:52 -------- d-----w- c:\program files\2BrightSparks 2009-10-19 18:33 . 2009-10-19 18:33 -------- d-----w- c:\users\All Users\Application Data\Freedom Scientific 2009-10-19 18:33 . 2009-10-19 18:33 -------- d-----w- c:\program files\ssce 2009-10-19 18:32 . 2009-10-19 18:32 -------- d-----w- c:\windows\system32\HJSMEM 2009-10-19 18:31 . 2009-10-19 18:33 -------- d-----w- c:\program files\Freedom Scientific 2009-10-18 18:39 . 2009-10-18 18:39 7168 ----a-w- c:\users\Administrator\Application Data\Thinstall\TextAloud\4000008500003i\PDFToText.exe 2009-10-18 18:39 . 2009-10-18 18:39 7168 ----a-w- c:\users\Administrator\Application Data\Thinstall\TextAloud\400000600002i\AcroRd32Info.exe 2009-10-18 18:39 . 2009-10-18 18:39 7168 ----a-w- c:\users\Administrator\Application Data\Thinstall\TextAloud\1000000b00002i\verclsid.exe 2009-10-18 18:25 . 2003-12-18 16:53 6656 ----a-w- c:\windows\system32\haspvdd.dll 2009-10-18 18:25 . 2003-12-18 16:53 383 ----a-w- c:\windows\system32\haspdos.sys 2009-10-18 18:25 . 2003-12-18 16:53 304640 ----a-w- c:\windows\system32\hlvdd.dll 2009-10-18 18:25 . 2004-01-31 18:14 420000 ----a-w- c:\windows\system32\drivers\hardlock.sys 2009-10-18 18:25 . 2003-12-18 16:53 47616 ----a-w- c:\windows\system32\drivers\haspnt.sys 2009-10-18 18:22 . 2009-10-18 18:22 -------- d-----w- C:\HaspEmulPE.XP 2009-10-18 18:10 . 2009-10-18 18:10 -------- d-----w- c:\users\Administrator\Application Data\Freedom Scientific 2009-10-18 18:07 . 2009-10-18 18:08 -------- d-----w- c:\program files\anReader 2009-10-18 16:54 . 2009-10-19 18:32 -------- d--h--w- c:\program files\Freedom Scientific Installation Information 2009-10-18 15:57 . 2009-10-18 15:57 -------- d-----w- c:\program files\Rainbow Technologies 2009-10-18 15:57 . 2008-10-07 13:33 6058112 ----a-w- c:\windows\system32\dcmc0d0.dll 2009-10-17 19:31 . 2009-07-23 09:56 714752 ----a-w- c:\windows\system32\drivers\SandBox.sys 2009-10-17 19:30 . 2009-07-13 11:19 256792 ----a-w- c:\windows\system32\drivers\afwcore.sys 2009-10-17 19:29 . 2009-10-17 19:31 -------- d-----w- c:\windows\system32\Filt 2009-10-17 19:29 . 2009-02-18 15:30 31128 ----a-w- c:\windows\system32\drivers\afw.sys 2009-10-17 19:28 . 2009-10-17 19:28 -------- d-----w- c:\program files\Agnitum 2009-10-17 19:28 . 2009-10-17 19:28 -------- d-----w- c:\users\All Users\Application Data\Agnitum 2009-10-17 17:52 . 2009-10-17 17:52 -------- d-sh--w- c:\users\LocalService\IETldCache 2009-10-17 15:50 . 2009-11-03 16:51 537576 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\aawapi.dll 2009-10-17 15:46 . 2009-10-17 15:46 -------- dc-h--w- c:\users\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6} 2009-10-17 15:46 . 2009-10-03 08:15 2924848 -c--a-w- c:\users\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe 2009-10-14 09:40 . 2009-07-17 16:22 1435648 ------w- c:\windows\system32\dllcache\query.dll 2009-10-14 09:37 . 2009-08-26 08:00 247326 ------w- c:\windows\system32\dllcache\strmdll.dll 2009-10-14 09:35 . 2009-09-04 21:03 58880 ------w- c:\windows\system32\dllcache\msasn1.dll 2009-10-13 22:35 . 2009-10-13 22:35 -------- d-----w- c:\program files\Search Guard PlusU 2009-10-13 22:35 . 2009-10-13 22:35 -------- d-----w- c:\program files\Search Guard Plus 2009-10-12 20:47 . 2008-03-05 14:03 329224 ----a-w- c:\windows\system32\DXErr.exe 2009-10-12 20:47 . 2008-03-09 05:25 236 ----a-w- c:\program files\Common Files\dx.reg 2009-10-12 20:47 . 2008-03-05 14:03 209416 ----a-w- c:\windows\system32\dxcpl.exe 2009-10-12 20:47 . 2006-11-02 10:46 167936 ----a-w- c:\windows\system32\dxgi.dll 2009-10-12 20:47 . 2006-11-02 10:46 39936 ----a-w- c:\windows\system32\dwmapi.dll 2009-10-12 20:47 . 2006-11-29 12:06 440080 ----a-w- c:\windows\system32\d3dx10.dll 2009-10-12 20:47 . 2006-11-02 10:47 1162656 ----a-w- c:\windows\system32\ntdllnew.dll 2009-10-12 20:47 . 2008-04-12 16:13 1029126 ----a-w- c:\windows\system32\d3d10.dll 2009-10-12 20:47 . 2009-10-12 20:45 716153 ----a-w- c:\windows\system32\unins000.exe 2009-10-12 20:46 . 2009-10-12 20:47 2733 ----a-w- c:\windows\system32\unins000.dat 2009-10-12 17:17 . 2009-09-04 15:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll 2009-10-12 17:17 . 2009-09-04 15:44 238936 ----a-w- c:\windows\system32\xactengine3_5.dll 2009-10-12 17:17 . 2009-09-04 15:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll 2009-10-12 17:17 . 2009-09-04 15:29 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll 2009-10-12 17:16 . 2009-09-04 15:29 235344 ----a-w- c:\windows\system32\d3dx11_42.dll 2009-10-12 17:16 . 2009-09-04 15:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll 2009-10-12 17:16 . 2009-09-04 15:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll 2009-10-12 17:16 . 2009-03-09 13:27 453456 ----a-w- c:\windows\system32\d3dx10_41.dll 2009-10-12 17:16 . 2009-03-09 13:27 1846632 ----a-w- c:\windows\system32\D3DCompiler_41.dll 2009-10-12 17:16 . 2009-03-09 13:27 4178264 ----a-w- c:\windows\system32\D3DX9_41.dll 2009-10-12 17:16 . 2009-09-04 15:44 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll 2009-10-12 17:16 . 2009-03-16 12:18 517448 ----a-w- c:\windows\system32\XAudio2_4.dll 2009-10-12 17:16 . 2009-03-16 12:18 235352 ----a-w- c:\windows\system32\xactengine3_4.dll 2009-10-12 17:14 . 2009-03-16 12:18 22360 ----a-w- c:\windows\system32\X3DAudio1_6.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-11-11 16:58 . 2009-08-17 12:10 -------- d-----w- c:\users\All Users\Application Data\Babylon 2009-11-11 16:32 . 2009-08-11 16:22 -------- d-----w- c:\program files\Mozilla Thunderbird 2009-11-11 16:29 . 2009-08-01 14:11 -------- d-----w- c:\users\All Users\Application Data\Spyware Terminator 2009-11-11 16:29 . 2009-08-01 14:11 -------- d-----w- c:\program files\Spyware Terminator 2009-11-11 16:00 . 2009-08-01 14:11 -------- d-----w- c:\users\Administrator\Application Data\Spyware Terminator 2009-11-11 08:39 . 2009-08-01 15:34 -------- d---a-w- c:\users\All Users\Application Data\TEMP 2009-11-11 08:21 . 2009-08-01 13:34 -------- d-----w- c:\users\All Users\Application Data\Microsoft Help 2009-11-10 19:55 . 2009-08-01 21:33 -------- d-----w- c:\users\Administrator\Application Data\Skype 2009-11-10 18:38 . 2009-08-06 23:24 -------- d-----w- c:\users\Administrator\Application Data\Thinstall 2009-11-10 18:03 . 2009-08-01 21:35 -------- d-----w- c:\users\Administrator\Application Data\skypePM 2009-11-08 18:02 . 2009-08-16 02:03 2285056 ----a-w- c:\windows\system32\TUKernel.exe 2009-11-08 17:51 . 2009-07-31 18:02 -------- d-----w- c:\users\Administrator\Application Data\BSplayer PRO 2009-11-07 23:00 . 2009-08-01 15:34 -------- d-----w- c:\users\Administrator\Application Data\URSoft 2009-11-07 19:49 . 2009-08-01 19:16 -------- d-----w- c:\program files\Paint.NET 2009-11-05 00:05 . 2009-08-01 11:41 -------- d-----w- c:\program files\Java 2009-11-04 15:10 . 2009-08-30 21:27 -------- d-----w- c:\program files\Farm Frenzy Pizza Party 2009-11-03 16:51 . 2009-10-02 15:30 862040 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe 2009-11-03 16:51 . 2009-10-02 15:30 15880 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe 2009-11-03 16:51 . 2009-10-02 15:30 206944 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll 2009-11-03 16:51 . 2009-10-02 15:30 390288 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll 2009-11-03 16:51 . 2009-10-02 15:30 370744 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll 2009-11-03 16:51 . 2009-10-02 15:30 163728 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll 2009-11-03 16:51 . 2009-10-02 15:30 194104 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\Savapibridge.dll 2009-11-03 16:51 . 2009-10-02 15:30 5908024 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll 2009-11-03 16:51 . 2009-10-02 15:30 87496 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll 2009-11-03 16:51 . 2009-10-02 15:30 327000 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll 2009-11-03 16:51 . 2009-10-02 15:30 933120 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll 2009-11-03 16:51 . 2009-10-02 15:30 640608 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\AutoLaunch.exe 2009-11-03 16:50 . 2009-10-02 15:30 815760 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe 2009-11-03 16:50 . 2009-10-02 15:29 822904 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe 2009-11-03 16:50 . 2009-10-02 15:29 1638104 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe 2009-11-03 16:50 . 2009-10-02 15:29 788368 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe 2009-11-03 16:50 . 2009-10-02 15:29 1179232 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe 2009-10-29 01:32 . 2009-08-01 11:28 -------- d-----w- c:\program files\Opera 2009-10-22 12:07 . 2009-08-17 12:10 -------- d-----w- c:\users\Administrator\Application Data\Babylon 2009-10-19 18:36 . 2006-11-20 12:27 2000000 ----atw- c:\windows\system32\HJSMEM.DAT 2009-10-19 18:28 . 2009-08-17 11:40 -------- d-----w- c:\users\All Users\Application Data\RFA_Backups 2009-10-18 18:54 . 2009-08-01 11:43 -------- d-----w- c:\program files\Common Files\Adobe 2009-10-17 18:24 . 2009-07-31 18:02 -------- d-----w- c:\users\Administrator\Application Data\Comodo 2009-10-17 18:24 . 2009-07-31 18:01 -------- d-----w- c:\program files\COMODO 2009-10-17 15:43 . 2009-08-01 14:49 -------- d-----w- c:\users\Administrator\Application Data\LimeWire 2009-10-11 03:17 . 2009-07-31 17:37 411368 ----a-w- c:\windows\system32\deploytk.dll 2009-10-05 00:18 . 2009-10-05 00:18 -------- d-----w- c:\program files\inSoft 2009-10-03 04:44 . 2009-08-01 14:36 -------- d-----w- c:\program files\Unlocker 2009-10-02 16:04 . 2009-08-04 23:13 -------- d-----w- c:\program files\RegistryFix7 2009-10-02 15:30 . 2009-08-04 14:41 15688 ----a-w- c:\windows\system32\lsdelete.exe 2009-10-02 15:30 . 2009-10-02 15:30 17632 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\WSCUpdate.dll 2009-10-02 15:30 . 2009-10-02 15:30 68640 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\64\lbd.sys 2009-10-02 15:30 . 2009-10-02 15:30 525792 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\64\DIFxAPI.dll 2009-10-02 15:30 . 2009-10-02 15:30 303976 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\64\AAWDriverTool.exe 2009-10-02 15:29 . 2009-10-02 15:29 640760 ----a-w- c:\users\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe 2009-10-01 16:56 . 2009-10-01 16:56 -------- d-----w- c:\program files\Microsoft 2009-09-28 14:43 . 2009-09-03 18:24 177024 ----a-w- c:\users\Administrator\Application Data\Mozilla\Firefox\Profiles\zdwvxrnz.default\FlashGot.exe 2009-09-27 11:48 . 2009-09-06 12:57 -------- d-----w- c:\users\Administrator\Application Data\mp3rocket 2009-09-23 12:55 . 2009-08-01 15:05 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys 2009-09-19 09:44 . 2009-09-19 09:44 -------- d-----w- c:\users\Administrator\Application Data\Search Settings 2009-09-19 09:44 . 2009-09-19 09:44 -------- d-----w- c:\users\Administrator\Application Data\Dealio 2009-09-18 23:36 . 2009-09-18 23:26 -------- d-----w- c:\users\Administrator\Application Data\WeatherWatcherLive 2009-09-18 22:30 . 2009-09-18 22:30 -------- d-----w- c:\program files\Eggiz 2009-09-18 22:29 . 2009-08-01 14:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-09-18 22:27 . 2009-08-01 18:15 -------- d-----w- c:\program files\MyFreeWeather 2009-09-18 22:16 . 2009-08-04 20:47 4045528 ----a-w- c:\users\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe 2009-09-18 11:15 . 2009-08-04 23:53 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-09-18 01:02 . 2009-09-16 22:29 -------- d-----w- c:\program files\Cosmopolitan 2009-09-18 01:02 . 2009-08-29 11:10 -------- d-----w- c:\program files\Amazing Adventures The Lost Tomb 2009-09-15 10:57 . 2009-09-09 16:47 -------- d-----w- c:\program files\UlisesSoft 2009-09-15 00:05 . 2009-09-15 00:02 -------- d-----w- c:\program files\Digital Photo Software 2009-09-15 00:03 . 2009-09-15 00:03 8854 ----a-r- c:\users\Administrator\Application Data\Microsoft\Installer\{25626A0D-9AF7-477D-BD62-B0C62B366983}\NewShortcut3_43405B1A6E07446F91523AC32617A818.exe 2009-09-15 00:03 . 2009-09-15 00:03 61440 ----a-r- c:\users\Administrator\Application Data\Microsoft\Installer\{25626A0D-9AF7-477D-BD62-B0C62B366983}\NewShortcut2_25626A0D9AF7477DBD62B0C62B366983_1.exe 2009-09-15 00:03 . 2009-09-15 00:03 61440 ----a-r- c:\users\Administrator\Application Data\Microsoft\Installer\{25626A0D-9AF7-477D-BD62-B0C62B366983}\NewShortcut1_25626A0D9AF7477DBD62B0C62B366983_1.exe 2009-09-15 00:03 . 2009-09-15 00:03 21630 ----a-r- c:\users\Administrator\Application Data\Microsoft\Installer\{25626A0D-9AF7-477D-BD62-B0C62B366983}\ARPPRODUCTICON.exe 2009-09-11 14:13 . 2009-03-08 09:01 136704 ----a-w- c:\windows\system32\msv1_0.dll 2009-09-11 07:08 . 2009-08-01 03:21 73264 ----a-w- c:\users\Default User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-09-10 12:54 . 2009-08-01 14:06 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-09-10 12:53 . 2009-08-01 14:06 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-09-06 10:53 . 2009-09-06 10:53 7680 ----a-w- c:\users\Administrator\Application Data\Thinstall\AMS Photo Effects 1.87\4000008000002i\Splash Screen.exe 2009-09-04 21:03 . 2008-04-14 03:42 58880 ----a-w- c:\windows\system32\msasn1.dll 2009-08-29 08:08 . 2009-03-08 09:12 916480 ----a-w- c:\windows\system32\wininet.dll 2009-08-26 08:00 . 2009-03-08 09:12 247326 ----a-w- c:\windows\system32\strmdll.dll 2009-08-23 14:53 . 2009-08-23 14:53 148736 ----a-w- c:\users\All Users\Application Data\hpe1E9A.dll 2009-08-23 14:53 . 2009-08-23 14:53 148736 ----a-w- c:\users\All Users\Application Data\hpe1E9A.dll 2009-08-21 22:16 . 2009-08-21 22:15 88 --sh--r- c:\users\All Users\Application Data\24993C8340.sys 2009-08-21 22:16 . 2009-08-21 22:15 88 --sh--r- c:\users\All Users\Application Data\24993C8340.sys 2009-08-21 22:16 . 2009-08-21 22:14 2516 --sha-w- c:\users\All Users\Application Data\KGyGaAvL.sys 2009-08-21 22:16 . 2009-08-21 22:14 2516 --sha-w- c:\users\All Users\Application Data\KGyGaAvL.sys 2009-08-20 19:15 . 2009-08-20 19:15 90112 ----a-w- c:\windows\Cuninst.exe 2009-08-15 20:36 . 2009-08-15 20:36 604416 ----a-w- c:\windows\system32\TUProgSt.exe 2009-08-15 20:36 . 2009-08-15 20:36 361216 ----a-w- c:\windows\system32\TuneUpDefragService.exe . ------- Sigcheck ------- [-] 2009-03-08 . FF267FF1D773BEA5522295E3A79701E9 . 361600 . . [5.1.2600.5649] . . c:\windows\system32\drivers\tcpip.sys [-] 2009-03-08 . 3D1ABDC3009D6B7CA7F9E66769C126CA . 568832 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe [-] 2009-03-08 . EA032FC150B9C6276C98EB3DED3B75C6 . 652800 . . [5.82] . . c:\windows\system32\comctl32.dll [-] 2009-03-08 . 99C1ACB1B8F0F2CECC56515E502B5120 . 575488 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll [-] 2009-03-08 . E1F5F729264C8AF1D6A95ECD1C8086DD . 1723904 . . [6.00.2900.5634] . . c:\windows\explorer.exe [-] 2009-03-08 . CBF5945651C96E471B3A004BBDC36864 . 37376 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RocketDock"="d:\ppapps\RocketDock\RocketDock.exe" [2007-09-02 495616] "Google Update"="c:\users\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-08-01 133104] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016] "egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-05-14 2029640] "SpywareTerminator"="c:\progra~1\SPYWAR~1\SpywareTerminatorShield.exe" [2009-08-01 2171904] "TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2009-05-26 4355512] "AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2009-05-26 960568] "Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2009-05-26 377248] "BigDog305"="c:\windows\VM305_STI.EXE" [2007-04-09 57344] "Babylon Client"="c:\program files\Babylon\Babylon-Pro\Babylon.exe" [2009-08-17 3959696] "AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080] "OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2009-07-24 1259336] "OutpostFeedBack"="c:\program files\Agnitum\Outpost Firewall Pro\feedback.exe" [2009-07-24 436552] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280] "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-10-07 1630208] "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-04-10 16861184] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2009-03-08 37376] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "NewUser"="c:\windows\LastXP\NewUser.cmd" [2009-02-18 2375] "_nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-03-08 128512] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "SynchronousMachineGroupPolicy"= 0 (0x0) "SynchronousUserGroupPolicy"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoSMConfigurePrograms"= 1 (0x1) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoSMConfigurePrograms"= 1 (0x1) [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer] "NoSMHelp"= 1 (0x1) "NoSMConfigurePrograms"= 1 (0x1) [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "UIHost"="c:\users\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"= "c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"= "c:\\Program Files\\Java\\jre6\\bin\\java.exe"= "c:\\Program Files\\Camfrog\\Camfrog Video Chat\\Camfrog Video Chat.exe"= "c:\\Program Files\\LimeWire\\LimeWire.exe"= "c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "5353:TCP"= 5353:TCP:Adobe CSI CS4 R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [1.8.2009 16:05 64288] R0 tdrpman228;Acronis Try&Decide and Restore Points filter (build 228);c:\windows\system32\drivers\tdrpm228.sys [1.8.2009 16:14 902592] R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [14.5.2009 14:47 107256] R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [14.5.2009 14:49 94360] R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [17.10.2009 20:31 714752] R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [1.8.2009 15:11 142592] R2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [17.10.2009 20:29 1312584] R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [14.5.2009 14:47 731840] R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [17.10.2009 20:29 31128] R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [17.10.2009 20:30 256792] R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [23.8.2009 15:58 27632] R3 ZSMC0305;A4 TECH PC Camera V;c:\windows\system32\drivers\usbVM305.sys [24.8.2009 16:53 391688] S2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [23.8.2009 15:52 90112] S2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [15.8.2009 21:36 604416] S3 ASWFilt;ASWFilt;c:\windows\system32\Filt\ASWFilt.dll [17.10.2009 20:31 33920] S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [24.9.2009 12:17 1179232] S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [23.8.2009 15:56 89256] --- Other Services/Drivers In Memory --- *NewlyCreated* - MBR *Deregistered* - mbr HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . Contents of the 'Scheduled Tasks' folder 2009-11-11 c:\windows\Tasks\1-Click Maintenance.job - c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-04-27 13:37] 2009-11-03 c:\windows\Tasks\Ad-Aware Update (Weekly).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 16:50] 2009-11-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-583907252-602162358-682003330-500Core.job - c:\users\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-01 11:12] 2009-11-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-583907252-602162358-682003330-500UA.job - c:\users\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-01 11:12] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.tattoodle.com?tid=0 uLocal Page = c:\windows\pchealth\helpctr\System\panels\blank.htm uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 mLocal Page = c:\windows\pchealth\helpctr\System\panels\blank.htm uInternet Settings,ProxyOverride = local uSearchURL,(Default) = hxxp://www.google.com/keyword/%s IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Crawler Search - tbr:iemenu IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000 IE: Translate this web page with Babylon IE: Translate with &Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm IE: Translate with Babylon Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll FF - ProfilePath - c:\users\Administrator\Application Data\Mozilla\Firefox\Profiles\zdwvxrnz.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=19&q= FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.tattoodle.com?tid={3392775D-2211-BE29-CDAA-662D033FFC9D} FF - prefs.js: keyword.URL - hxxp://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v=19&tid={3392775D-2211-BE29-CDAA-662D033FFC9D}&q= FF - component: c:\program files\Crawler\Toolbar\firefox\components\xcomm.dll FF - component: c:\program files\Crawler\Toolbar\firefox\components\xshared.dll FF - component: c:\program files\Crawler\Toolbar\firefox\components\xsupport.dll FF - component: c:\program files\Crawler\Toolbar\firefox\components\xwsg.dll FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll FF - plugin: c:\program files\Opera\program\plugins\nppl3260.dll FF - plugin: c:\program files\Opera\program\plugins\nprpjplug.dll FF - plugin: c:\users\Administrator\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX POLICIES ---- FF - user.js: network.http.max-persistent-connections-per-server - 4 FF - user.js: nglayout.initialpaint.delay - 600 FF - user.js: content.notify.interval - 600000 FF - user.js: content.max.tokenizing.time - 1800000 FF - user.js: content.switch.threshold - 600000 . - - - - ORPHANS REMOVED - - - - BHO-{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - c:\program files\Dealio Toolbar\DealioToolbarIE.dll Toolbar-{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - c:\program files\Dealio Toolbar\DealioToolbarIE.dll ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-11-11 17:58 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... HKLM\Software\Microsoft\Windows\CurrentVersion\Run BigDog305 = c:\windows\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)???????????????????0?????????@?????????????? scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-583907252-602162358-682003330-500\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (Administrator) "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ea,a0,9b,f9,2d,65,b0,4a,8f,64,f9,\ "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ea,a0,9b,f9,2d,65,b0,4a,8f,64,f9,\ . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(1656) c:\windows\system32\SETUPAPI.dll c:\windows\system32\COMRes.dll c:\windows\system32\cscui.dll - - - - - - - > 'lsass.exe'(1736) c:\windows\system32\wdigest.dll c:\windows\system32\setupapi.dll - - - - - - - > 'explorer.exe'(2564) c:\windows\system32\SHDOCVW.dll c:\windows\system32\WININET.dll c:\windows\system32\msctfime.ime c:\windows\system32\COMRes.dll c:\windows\System32\cscui.dll c:\windows\system32\wpdshext.dll c:\windows\system32\portabledeviceapi.dll c:\windows\system32\SETUPAPI.dll c:\windows\system32\audiodev.dll c:\windows\system32\WMVCore.DLL c:\windows\system32\WMASF.DLL c:\program files\Babylon\Babylon-Pro\Captlib.dll c:\windows\system32\MSVCP60.dll c:\windows\System32\wiadefui.dll c:\windows\system32\msi.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\wpdshserviceobj.dll c:\windows\system32\portabledevicetypes.dll c:\windows\system32\NETSHELL.dll c:\windows\system32\credui.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Common Files\Acronis\Schedule2\schedul2.exe c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\nvsvc32.exe c:\program files\Spyware Terminator\sp_rsser.exe c:\windows\system32\RUNDLL32.EXE . ************************************************************************** . Completion time: 2009-11-11 18:05 - machine was rebooted ComboFix-quarantined-files.txt 2009-11-11 17:05 Pre-Run: 7.418.703.872 bytes free Post-Run: 7.526.789.120 bytes free - - End Of File - - D808589F4A46F6AB8ED13B45495DCFCC Molim nekoga za pomoc! [Ovu poruku je menjao xman25 dana 11.11.2009. u 18:31 GMT+1] |
pri pokretanju Mozille ali kada sam isao na OK Mozilla se normalno otvori. Od danas nakon pojavljivanja ove poruke Mozilla nece da se otvori vec izbaci ovu poruku: 

